ACTG 55: INFORMATION SYSTEMS & CONTROLS (ISC)
Foothill College Course Outline of Record
Heading | Value |
---|---|
Effective Term: | Summer 2025 |
Units: | 5 |
Hours: | 5 lecture per week (60 total per quarter) |
Prerequisite: | ACTG 1A or 1AH. |
Degree & Credit Status: | Degree-Applicable Credit Course |
Foothill GE: | Non-GE |
Transferable: | CSU |
Grade Type: | Letter Grade (Request for Pass/No Pass) |
Repeatability: | Not Repeatable |
Student Learning Outcomes
- Explain the IT audit and advisory services, SOC engagements and the management of financial information.
- Explain business processes and internal controls, risks associated with IT and controls, and data management relationships
Description
Course Objectives
The student will be able to:
- Explain information technology (IT) governance and strategy, and demonstrate overall awareness of IT standards
- Explain basics of assurance-related research and techniques
- Explain IT systems, controls, and resources; identify risks to information systems and the organizational risk appetite
- Demonstrate awareness of IT risks and their related business impact
- Identify IT control frameworks
- Identify IT control activities (ITGC)
- Identify and evaluate appropriate application controls
- Explain IT change management risks and processes
- Recognize the basics of cybersecurity and risk management
- Analyze and evaluate the flow of transactions in a system interface diagram to identify risks
- Determine logical access controls and prepare results of appropriate tests of security
- Perform tests and report on the results of change management controls
- Design appropriate tests of the application controls related to business processes
- Identify additional procedures needed to obtain sufficient appropriate evidence due to data analytic procedures
- Recognize the basics of SOC engagements and SOC reports
- Identify scope considerations for the SOC engagement and complementary controls
- Perform SOC engagement procedures
- Explain SOC reports, considerations, exceptions, and distribution
- Recognize the basics of a data governance program
- Identify basics of data extraction, preparation, and manipulation
- Identify and define information security and privacy frameworks and their associated risks
- Recognize the basics of business resiliency
- Recognize the basics of business continuity
Course Content
- IT governance and risk assessment
- IT governance, strategy, and standards
- Assurance-related research
- Business processes and the design of IT internal controls
- IT risk identification and assessment
- IT control frameworks
- IT general controls (ITGC)
- Application controls
- IT change management
- Cybersecurity risk management
- System interfaces/flow of data
- Performing procedures, tests of internal controls
- Logical access controls
- IT change management
- Tests of internal controls related to business processes
- Sufficient appropriate evidence: specific matters that require special consideration
- SOC engagements
- Basic concepts
- SOC engagement: planning
- SOC engagement: performing procedures
- SOC engagement: reporting
- Use and management of data
- Data governance
- Data preparation/manipulation
- Information security and protection of information assets
- Information security and privacy frameworks, and standards
- Business resiliency
- Business continuity
Lab Content
Not applicable.
Special Facilities and/or Equipment
2. When taught as an online distance learning section, students and faculty need reliable and ongoing internet (Java-enabled) and email access.
Method(s) of Evaluation
Quizzes
Exams
Class participation
Homework
Assignments requiring the use of general ledger software, spreadsheet, word processor, and presentation applications, such as QuickBooks, MS Excel, MS Word, and MS PowerPoint, respectively
Team projects
Research assignments
Case study analysis
Oral and/or written presentations
Method(s) of Instruction
Lecture
Electronic discussions
Group work
Case studies
Representative Text(s) and Other Materials
Gleim, Irvin N., Garrett W. Gleim, and William A. Hillison. Gleim CPA Information Systems & Controls (ISC). 2024.
Romney, Marshall B., Paul J. Steinbart, Scott L. Summers, and David A. Wood. Accounting Information Systems, 16th ed.. 2023.
Arens, Alvin A., Randal J. Elder, Mark S. Beasley, and Chris E. Hogan. Auditing and Assurance Services, 18th ed.. 2023.
Types and/or Examples of Required Reading, Writing, and Outside of Class Assignments
- Students will be expected to read approximately 40 pages per week, in addition to completing associated assignments for an estimated total of 10 hours out-of-class commitment per week
- Applying basic Excel commands to prepare financial statements, bank reconciliation, budgets, and accounting reports
- Reading of corporate annual reports
- Writing assignment responding to questions related to the corporate annual reports of publicly-held corporations
- Written research paper and/or project
- Reading of internet articles and writing on accounting topics or accounting-related current events and/or careers
- Reading Wall Street Journal, Business Week, and Fortune